Page 33 of 51
© Copyright 2017 Oracle Corporation
This document may be freely reproduced and distributed whole and intact including this Copyright notice.
2.7.4 Encryption Enabled Cryptographic Keys and Critical Security Parameters
The cryptographic keys, key components, and other CSPs used by the module while operating in either the Permanent
Encryption Approved Mode or Encryption Enabled Approved Mode are shown in Table 9.
Table 9 – List of Cryptographic Keys, Cryptographic Key Components, and CSPs (Permanent Encryption and Encryption Enabled Modes)
Key
Key Type
Generation / Input
Output
Storage
Zeroization
Use
Media Key (MEKey) AES CCM 256-bit
Generated externally;
Input encrypted via
AKWK
Output encrypted via
DEKey
Plaintext in RAM
49
and FPGA
50
“Reset” service;
Switch Approved
Mode
To encrypt and decrypt
data to and from
magnetic tape
AES Key Wrap Key
(AKWK)
AES ECB 256-bit
Generated internally
via Approved DRBG
Output encapsulated
via KWKPublicKey
Plaintext in RAM
“Reset” service;
Power cycle;
Switch Approved
Mode
Decrypt MEKey
Dump Encryption
Key (DEKey)
AES CCM 256-bit
Generated internally
via Approved DRBG
Output encrypted via
DEPubKey
Plaintext in RAM
“Reset” service;
Power cycle;
Switch Approved
Mode
Encrypt dump files
Dump Encryption
Public Key
(DEPubKey)
RSA 2048-bit public
key
Generated externally;
Hardcoded into
module
Output encrypted via
DEKey
Plaintext in
EEPROM and RAM
Not Applicable
Encapsulate DEKey
Tape Drive Private
Key (TDPrivKey)
RSA 2048-bit
private key
Generated externally;
Input via TLS_ECK
Output encrypted via
DEKey
Plaintext in RAM
and EEPROM
“Reset” service;
Switch Approved
Mode
Authenticate the
module to OKM cluster
appliance during TLS
session
Tape Drive Public
Key (TDPubKey)
RSA 2048-bit public
key
Generated externally;
Input via TLS_ECK
Output encrypted via
DEKey; Output in
plaintext
Plaintext in
EEPROM and RAM
“Reset” service;
Switch Approved
Mode
Authenticate the
module to OKM cluster
appliance during TLS
session
49
RAM – Random Access Memory
50
FPGA – Field Programmable Gate Array